Hey,

On Tue, 2026-07-07 at 11:13 -0700, Ryan Lee via AppArmor wrote:
> This is a preparatory cleanup for switching to a condref version of
> refreshing the parent label.
> 

LGTM,

Acked-by: Georgia Garcia <[email protected]>
> Signed-off-by: Ryan Lee <[email protected]>
> ---
>  security/apparmor/policy.c | 10 +++++++---
>  1 file changed, 7 insertions(+), 3 deletions(-)
> 
> diff --git a/security/apparmor/policy.c b/security/apparmor/policy.c
> index f6f1b72d7c3d..9475f6455542 100644
> --- a/security/apparmor/policy.c
> +++ b/security/apparmor/policy.c
> @@ -1145,10 +1145,14 @@ static struct aa_profile 
> *update_to_newest_parent(struct aa_profile *new)
>  
>       /* parent replaced in this atomic set? */
>       if (newest != parent) {
> -             aa_put_profile(parent);
>               rcu_assign_pointer(new->parent, newest);
> -     } else
> -             aa_put_profile(newest);
> +     }
> +     /* Unconditionally put the parent:
> +      * If parent != newest, we aren't using the parent anymore
> +      * If parent == newest, we got an extra ref to it, so put it and
> +      *   retain the other ref we have to newest
> +      */
> +     aa_put_profile(parent);
>  
>       return newest;
>  }


Reply via email to